Aller au contenu

Fiche vulnérabilité

CVE-2024-47575 : faille exploitée fortinet fortimanager (CVSS 9.8)

Description

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
23 oct. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • fortinet fortimanager
  • fortinet fortimanager cloud

Correctif et mesures

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE